Rate limits for API users

AI-generated summary

Rate limits for API users

The discussion revolves around rate limits for API users, particularly for users who intend to post topics or data via API keys. AstonJ initially asked about rate limits and the possibility of bypassing them for trusted accounts.

According to fefrei and sam, using an API key bypasses some rate limits, but not those enforced by nginx. AstonJ and frizman21 expressed concerns about hitting rate limits, especially when posting data via the API.

sam explained that there are explicit global limits for API users, which can sometimes cascade. However, for trivial GET requests, the API rate limit can be lifted. sam recommended reading the rate limits documentation on GitHub and Discourse meta.

AstonJ summarized the findings, providing links to the relevant documentation on global rate limits and throttling in Discourse.

I want to create a sister app at some point that will post topics on to the forum via an API user account - is there any info available on rate limits for this? Can we ‘trust’ certain accounts so that rate limits do not apply?

As far as I know, using an API key (generated in the admin interface) bypasses rate limits that are checked within the rails stack, e.g. limits on the number of posts.
It will not bypass the general limit on the number of requests per second enforced by nginx, but most likely, that won’t be a problem :slight_smile:

You can explicitly bypass validations if you are using the API and API key, the limits in general will hold though.

I’m not too bothered by validations Sam, but by-passing rate limits for specific accounts could be helpful.

Does the response include the specific error code if rate limits have been by-passed? That could be helpful if there’s no chance of including an option to by-pass..

I kind of worry about answering questions about problems that do not exist :blush:

If you hit the limits let me know and let me know what errors you are getting

I did actually hit the limit previously - we currently have 6 monthly giveaways and every night a cron runs to check whether there is a ‘bonus day’, if there is, it posts an update on the forum. What I was finding was the crons running later weren’t posting. However I’ve since changed the cron jobs to run a minute after each other. (This is fine for this situation.)

I’ll keep you posted re the other app (which will be posting via the API much more frequently) though I don’t expect this to go live for a few months yet.

We use discourse via API from a Rails server. Which means all the traffic coming from one IP. We have enough traffic that it hits the rate limiter. I second the need for an API exception to this rate limit.

오늘 @sam 이/가 여기에 코멘트를 달기 좋은 주제일 것 같은데요 — 셀프 호스터에게는 제한이 있나요? 우리 쪽에도 제한이 있나요? 상황이 변했으니, 이 문제를 어떻게 생각하고 계신가요…

요즘에는 API에 대해 명시적인 전역 제한이 설정되어 있지만, 때로는 제한이 연쇄적으로 적용됩니다.

일부 컨트롤러는 N초당 생성할 수 있는 최대 주제 수와 같은 제한을 도입합니다.

간단한 GET 요청의 경우, API 속도 제한을 상당히 높여도 Discourse의 어떤 제한에도 도달하지 않을 수 있습니다. 그러나 NGINX에서도 조정해야 하는 일부 제한이 여전히 존재합니다.

이 경우 API 키를 사용하여 새 주제나 게시글을 작성하려는 계정에 어떤 영향을 미칠까요, Sam?

이것을 어디서 설정할 수 있나요, Sam?

또한 현재 포럼에서 많은 데이터를 가져오기 위해 discourse_api 지엄을 사용할 포털을 구축하는 것을 고려 중인데, 여기서 속도 제한에 도달할 가능성이 있을까요? '안전’으로 표시한 계정에 대해서는 속도 제한을 우회할 수 있으면 좋겠습니다.

여기에서 저희의 속도 제한(rate limits)을 읽어보시는 것을 추천합니다:

meta에 다양한 기타 제한 사항에 대한 문서가 흩어져 있을 것입니다.

샘, 감사합니다. 앞으로 참고할 수 있도록 (그리고 나중에 이 내용을 검색하는 다른 사람들을 위해) 전체 세부 사항을 공유합니다:

프라이빗 IP에 대해 질문이 있지만, 메인 토픽에 게시하겠습니다. 이 토픽은 다른 토픽이 더 최신이므로 이 시점에서 닫아도 될 것 같습니다.